πŸ” CVE Alert

CVE-2026-102784

UNKNOWN 0.0

Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.

CWE CWE-352
Vendor balbooa.com
Product gridbox extension for joomla
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for balbooa.com gridbox extension for joomla

Be the first to know when new unknown vulnerabilities affecting balbooa.com gridbox extension for joomla are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

balbooa.com / Gridbox extension for Joomla
1.0.0-2.20.3.1

References

NVD β†— CVE.org β†— EPSS Data β†—
balbooa.com: https://www.balbooa.com/gridbox

Credits

Sergiy Tryzhychynskyi